CtrlK
BlogDocsLog inGet started
Tessl Logo

threat-hunting

Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology. Use when the user mentions 'threat hunting,' 'proactive hunt,' 'TaHiTI,' 'PEAK framework,' 'MITRE ATT&CK hunt,' 'hypothesis-driven hunt,' 'hunt hypothesis,' 'living off the land,' 'LOLBins,' 'beaconing,' 'lateral movement detection,' 'data staging,' 'persistence hunting,' or wants to find threats that have evaded existing detections.

68

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

77%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers a well-sequenced, highly actionable hunting methodology with a dense technique catalog, executable-ish queries, and a clean report template. Its main structural weakness is that it is fully monolithic — the large hunt catalog and tool list should be split into reference files to keep the always-loaded SKILL.md lean, and a couple of the example queries contain syntax errors that would fail on first paste.

Suggestions

Move the 'High-yield hunt catalog' and 'Tools' sections into a references/hunt-catalog.md file, keeping a 2-3 line category summary in SKILL.md with a clearly signaled one-level-deep reference.

Fix the example queries so they are copy-paste ready: replace the invalid KQL `| where contains("198.51.100.42")` with a valid pattern (e.g., `| where * has "198.51.100.42"` on a projected field) and use `mvcount(values(Details))` in the Splunk example instead of `len(values(Details))`.

Trim editorial commentary such as 'the most actionable hunting methodology I've seen' and condense the opening cross-reference paragraph to a single line per skill to tighten token efficiency.

DimensionReasoningScore

Conciseness

The body is dense and high-yield — hunt catalog entries are one-line technique + telemetry pairs, and there is no padding explaining what a SIEM or ATT&CK is. Minor trims are possible (e.g., the editorializing "the most actionable hunting methodology I've seen" and the somewhat padded cross-references paragraph), which places it at 'efficient; minor instances of over-explanation' rather than the fully lean top anchor.

4 / 5

Actionability

Guidance is largely executable: three SIEM query examples, specific Sysmon/Windows EventCodes per hunt idea, concrete hypothesis examples, and a copy-paste report template. It falls short of 5 because some example queries have syntax gaps — the Sentinel pivot uses `| where contains("198.51.100.42")`, which is not valid KQL, and the Splunk example's `| where len(values(Details)) > 1` would need `mvcount` — fitting 'concrete code with minor gaps' rather than fully copy-paste ready.

4 / 5

Workflow Clarity

The PEAK methodology gives a clear four-step sequence (Prepare, Execute, Act, Knowledge) with hypothesis quality criteria, ranked hypothesis sources, three explicit execution patterns, an outcome-triage decision table for every hit (malicious/benign/unknown with next actions), and the rule "Don't leave hits in the 'unknown' state" acting as a validation checkpoint. The report template's checklists and the escalate-don't-continue boundary complete the feedback structure. Hunting is not a destructive/batch operation, so no validation cap applies.

5 / 5

Progressive Disclosure

Section structure is good and clearly organized, but the skill ships no bundle files at all, and ~90 lines of hunt catalog plus the tool list are exactly the bulk reference content that belongs in a separate file (e.g., references/hunt-catalog.md) with the body keeping an overview plus a pointer. That fits 'some structure; content that should be separate is inline' — not score 2, because headers and navigation within the single file are genuinely well organized, and not score 4, because there are no bundle files to point to.

3 / 5

Total

16

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: third-person, concrete about what the skill does, and equipped with an explicit and unusually rich 'Use when' trigger clause covering frameworks, jargon, and plain-language phrasings. Minor overlap risk with adjacent security skills on a few technique-level terms keeps it just short of top marks on specificity and distinctiveness.

DimensionReasoningScore

Specificity

The description names several concrete actions — "Conduct proactive, hypothesis-driven threat hunts", "search SIEM / EDR / logs for adversaries who haven't tripped an alert yet", "find threats that have evaded existing detections" — plus a named methodology (ATT&CK-driven). It stops short of score 5 because the actions are framed at methodology level rather than enumerating a comprehensive set of concrete capabilities (e.g., writing hunt queries, producing hunt reports, pivoting on IOCs), and score 3 is excluded because it clearly goes beyond 1-2 generic actions.

4 / 5

Completeness

It explicitly answers both parts: the 'what' ("Conduct proactive, hypothesis-driven threat hunts — search SIEM / EDR / logs for adversaries who haven't tripped an alert yet. ATT&CK-driven, hypothesis-based methodology.") and the 'when' via a full "Use when the user mentions..." clause listing concrete trigger phrases. This matches the top anchor exactly; the third-person voice is also correct, so no voice penalty applies.

5 / 5

Trigger Term Quality

Trigger coverage is comprehensive and natural: 'threat hunting', 'proactive hunt', 'hunt hypothesis', 'hypothesis-driven hunt', 'PEAK framework', 'TaHiTI', 'MITRE ATT&CK hunt', plus technique-level synonyms users would actually say ('living off the land', 'LOLBins', 'beaconing', 'lateral movement detection', 'data staging', 'persistence hunting') and a plain-language catch-all ("wants to find threats that have evaded existing detections"). This matches the anchor for comprehensive coverage including synonyms; no common phrasing is obviously missing.

5 / 5

Distinctiveness Conflict Risk

The proactive-hunting niche is clearly delimited ("adversaries who haven't tripped an alert yet") and most triggers ('PEAK framework', 'hunt hypothesis', 'TaHiTI') are unambiguous. A few terms — 'persistence hunting', 'lateral movement detection', 'LOLBins' — could plausibly fire for adjacent detection-engineering or incident-response skills, so it sits at 'mostly distinct; minor overlap risk' rather than the fully distinct top anchor.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.